geedge.lantern.io
export/sales confidence: high public

Three independent internal ops/monitoring codebases — nms/nmsweb, nms/oam ("gloam"), and nezha/nz-web — each maintain a dedicated Kazakhstan-specific branch (nmsweb/oam: "k18-1.0"; nezha: "2.0-kz-2021-07-05" and later kz tags), and nmsweb additionally ships Russian-language localization (globalMessages_ru_RU.properties) plus topology icons for named inline-device hardware models (ADC-A016, ASEM-T102) and generic network elements (BlockRouter, ISPnInlineDevice, CoreSwitch) — confirming K18 = Kazakhstan (per existing taxonomy) received custom-built monitoring/OAM software, not just shared config.

9b39c65447fc174d9c4bec51ea290b4eb2b9a811 refs/heads/k18-1.0 ; 86131ad99acacc971bc4e33bee48ac55c16fbf34 refs/heads/2.0-kz-2021-07-05
censorskz
capabilitydeployment-config

extracted_by: claude-sonnet-5 · added 2026-08-26 · id: 2026-nms-k18-branches-0f8b3a

Related findings

deployment

pangu_valve.conf explicitly binds the 'PanguValve' traffic-control daemon (阀门, ASMIS_PROC_NAME=Pangu/PanguValve) to the Astana, Kazakhstan (K18) site — REMOTE_DIR=ASTANA and a MAAT_EFFECTIVE_RANGE tag of location=Astana — and configures it to receive live rule updates from a MAAT Redis backend rather than static files, tying this enforcement component directly to a real-time MAAT rule-dispatch pipeline at a named export deployment.

export/sales

The T1/NTC (text-content DPI) node's wired-config manifest (main.conf, dated 2019-01-30) sets REMOTE_DIR=ASTANA/KAZAKHTELECOM/, directly naming Kazakhtelecom — Kazakhstan's dominant state-linked telecom operator — as the carrier context for this K18 deployment. The NTC_MAAT module's EFFECTIVE_FLAG further scopes rules to {location: Astana, isp: Tanstelecom}, naming a second Kazakhstani ISP (Transtelecom) tied to the same deployment.

export/sales

The tango/adc_hardware repo ([email protected], 2019-2021) contains a dedicated "K18 演示环境交换板配置" (K18 demo-environment switch board config) commit and a nezha_monitor_K18/ directory of NEZHA monitoring dashboards/alert rules for "ADC" hardware. This is direct evidence that Geedge's ADC compute-board hardware line (documented elsewhere as used for the Pakistan/WMS-UTR site) is also deployed for the K18 (Kazakhstan) site.

deployment

A recurring weekly 'Tiangou Secure Gateway — Server IP and Location of Overview' report, spanning Jan 2023 through Jan 2024 in this batch alone, tracks per-app top server IPs/geolocations/bytes for named foreign platforms (Instagram, Netflix, Reddit, Skype, Pinterest, Quora, Line, Likee, Medium, Pandora). Top consumer-side IP rows consistently resolve to Kazakhstan cities (Almaty, Pavlodar, Nur-Sultan/Astana), matching the K18 site codename. Processed-row counts grow roughly 10x over the year (889B rows/week in Jan 2023 to 9.4T rows/week in Jan 2024), and one instance reports Total Bytes Transferred of 14.66 PB and an average of 218.34 Gbps for a single week.

deployment

A custom Prometheus-backed infrastructure-monitoring platform (MySQL schema dumped from source "nz-prometheus", schema "nz-temp", dated 2020-10-16) has its sys_area reference table seeded with exactly the five Kazakhstan cities named in the K18 site-codename entry — Aktau, Almaty, Nur-Sultan (the pre-2022 name for Astana), Karaganda, and Zhezkazgan — and a companion live alert-message dump (dated Nov 2020) shows real "endpoint down" P2 alerts tagged Data center: Nur-Sultan / Aktau, Project: ADC, across modules named MXN-NODE and MCN0-3-NODE/SRV, pushing the earliest confirmed evidence of the K18 Kazakhstan deployment back to at least October-November 2020.

detection

Commit history for the K18 (Kazakhstan) argus-ntc console reveals its concrete feature set: a scheduled "网页关键字定时器" (webpage-keyword timer/scheduler) for keyword filtering, ASN/IP block-list configuration pages, a "BGP泛收" (BGP wide-collection) page, an SSL-interception config toggle, a file-scanning results page with MALWARE TYPE/MALWARE NAME columns, app-identification entries including a WhatsApp rename, and a VoIP business-config approval workflow, with blocking actions relabeled from "阻断" (block) to "封堵(丢弃)" (interdict/drop).